T Techclick ← All lessons
Zscaler · Risk360 · Interactive lesson

Risk360 score then the factor

Ticket: the CISO pack shows High and application owners say the number is not a work item. They are right. Risk360’s organisation score is an average of four attack-stage categories. Work starts when you open the contributing factor, read Your Score (0 is healthy), the entity, and the recommended action — then change the owning control, not the slide.

16 min read · L2 primary · Quiz at end

After this page you can

Lessons · Zscaler series · Risk360 exposure scoring

This page vs ZIA User Risk Score and EASM

This lesson is Risk360 organisation exposure scoring: four attack-stage categories, weighted factors, recommended actions. ZIA User Risk Score is a different object (pre-/post-infection behaviour on a user, can feed Risk360). Internet-facing inventory without a Risk360 factor is a different product class — see Xpanse if that is the ticket.

Zero Trust Exchange factory · ZIA DLP · Cortex Xpanse attack surface

Hero · four categories average into one org score; work is the factor
Four category panes External, Compromise, Lateral, Data Loss feeding an org-score cube that drills to a factor card
Mood, not a field list. Exact objects are in the SVG: org score is the average of four categories; High Impact Recommendations and the Factors drawer are where the ticket lives. No tenant integers are invented on this page.
Quick answer

Risk360 scores cyber risk at organisation level as the average of External Attack Surface, Compromise, Lateral Propagation and Data Loss. Documented org bands: Low 0–25, Medium 26–50, High 51–75, Critical 76–100. Each contributing factor has a risk weight, a Your Score (0 = healthy), severity (critical / high / medium), entities (workforce, 3rd parties, applications, assets), a Licensed? flag and a recommended action. Fix the owning control (ZIA, ZPA, seed domain, or a Data Fabric connector). Proof is the factor’s Last 30 Days trend and Your Score moving toward 0 — not peer rank and not a closed ticket.

Why the org number is not a ticket

The day-one ticket is always the same: “Risk360 is High, make it green.” Wrong object. The dashboard number is an average across four attack stages. Owners cannot patch an average. They can patch an exposed server, a malware outbreak, a segmentation gap, or uploads to a risky app — the examples Zscaler itself uses as score inputs.

Three silent-stuck states look identical from the board pack (a High tile):

Do not invent a tenant score, and do not chase peer

This page never assigns a fake integer to lab.example. Use the documented band (High = 51–75) and the factor fields. Peer score is a comparison strategy (default Zscaler-defined, or custom industry / region / revenue). Beating peers is not remediation. Monte Carlo dollars on Financial Risk are a loss estimate, not the org score.

Score, category, factor, entity

An organisation risk score is the average of the four category scores. Hover the dollar symbol for financial estimates; View Details opens Financial Risk. That is a different page. Category scores still have to be explained by factors.

A factor is the quantified condition. Risk360 weights it, adds it to the org score, and maps it to frameworks such as MITRE and NIST. Your Score on the factor depends on severity; 0 is a healthy score. Last 30 Days is the trend graph. Entities name who or what is affected. Recommended Actions are how you drive the factor toward healthy — if Licensed? is Y.

Path · score, then category, then factor, then the fix
Four glass panels labeled Score, Category, Factor, Fix
Feel of the order. Exact Admin objects — Dashboard bands, Top 10 Factors, Insights Explore, Seeds Management — are in the SVG and runbook. Do not read “Fix” as “exclude the entity.”

Org score

Average of four categories. Bands: Low 0–25, Medium 26–50, High 51–75, Critical 76–100. GUI: Dashboard (Experience Center: Analytics › Risk360).

Category

External Attack Surface (exposed servers, ASNs). Compromise (events, configs, traffic). Lateral Propagation (private access / segmentation). Data Loss (sensitive-data attributes).

Factor

Weighted input. Fields: Factor Name, Category, Your Score, Last 30 Days, Entities, Licensed?, Recommended Actions. List View = attack-based; Tree View = entity-based.

Entity

Workforce (risky user activity), 3rd Parties (contractors), Applications (unsanctioned / weaker SaaS), Assets (exposed organisational assets). Filter tiles on Tree View.

Say this out loud

The org score is an average of four stages. I do not fix the average. I open the factor, read the entity and the recommended action, change the owning control, then watch Your Score toward 0.

Dashboard → factor → recommended action

Read the dashboard first, but do not stop there. Identify which of the four categories moved. Open Top 10 Factors (View All → Factors) or High Impact Recommendations (Explore / View All → Insights). On the factor, the drawer has Details (severity, recommended actions, description, help link, jump to the responsible Zscaler service), Notes, and related problems. Insights lists the problem statement plus the recommendation. Investigate is where you can include or exclude an entity — with an Entity Override Note, which lands in audit logs.

Flow 1 · High band on the org tile, owners say “not a ticket”
1 Dashboard org · High 51–75 2 Category which of four moved 3 Factor Your Score · 0 = ok 4 Action Licensed? Y / N 5 Control ZIA / ZPA / seed 6 Proof = Last 30 Days + Your Score toward 0 Lab: External Attack Surface · factor example “exposed servers” · entity Assets · seed lab.example Insights Explore → Investigate. Include/exclude requires Entity Override Note (audit). Stop at step 1: owners get a High tile and no factor. That is the original ticket. Do not globally block ZIA to “move the average.” Do not exclude the entity to fake a drop. Licensed? = N: the factor is still scored; the recommended action needs a feature this tenant does not have. Source: About the Dashboard in Risk360; About Factors; About Insights.

Read left → right, then the gold bar. Route the human to the factor before anyone debates the average.

ObjectLab / documented valueIf missing
Org score bandHigh (51–75) — documented range, not an invented tenant integerYou are arguing a colour. Open the four category scores.
CategoryExternal Attack Surface (lab) — exposed servers / ASNsAverage hides a quiet Compromise next to a loud External.
Seed domainlab.example · max 10 domains · first scan 24–48 h · weekly afterEAS factors stay empty or stale. Score is not “safe”; it is under-fed.
FactorDashboard example: exposed servers · Your Score not 0 · Severity HighNo work item. Owners are correct that the org tile is not actionable.
EntitiesAssets (lab). Also Workforce, 3rd Parties, ApplicationsCannot assign an owner. Tree View filter tiles are empty of meaning.
Licensed?Y or N for the feature the recommended action needsN: do not call the factor a false positive. Escalate licence or pick another action.
Recommended actionDrawer + Insights problem/recommendation · ExploreYou will change the wrong ZIA rule. Follow the jump link to the responsible service.
Closure proofLast 30 Days down · Your Score toward 0Jira Resolved while the factor graph is flat. Board pack still High.

Factor vs peer vs dollars vs asset score

Pick the pane for the question you are actually answering. Mixing them is the usual “we beat peers so the exposed server is fine” ticket.

Flow 2 · four numbers, four jobs
Org score average of 4 stages Low 0–25 … Crit 76–100 Dashboard tile Factor score Your Score · 0 = healthy weight + severity this is the work item Peer score comparison strategy industry / region / revenue not a recommended action Financial risk Monte Carlo $ estimate hover dollar · View Details not the org average Asset-level risk (Assets page) is a later drill — 65+ indicators, pre- and post-infection behaviour — not a substitute for the org average. ZIA User Risk Score is a user object that can feed Risk360. Do not reset a user to Low and call the org factor closed. Third-party factors (CrowdStrike CrowdScore, Qualys/Tenable/Rapid7/Wiz/MDE vulns) need a Data Fabric connector. Empty connector ≠ healthy factor. Source: About the Dashboard; About Factors; Viewing Asset-Level Risk; Integrating 3rd-Party Connectors.

Four columns, four tickets. The gold panel is the only one that names a recommended action.

NeedUseSkip
What should ops do this week?Factors List View + High Impact Recommendations / InsightsOrg tile alone, or peer rank.
Who is affected?Tree View entity tiles: Workforce, 3rd Parties, Applications, AssetsMailing security@ with the average.
Board $ exposureFinancial Risk · Monte Carlo (optionally Simulate breach probability)Treating the dollar hover as a factor score.
Are we worse than industry?Peer Score Settings (default Zscaler-defined, or custom vertical / region / revenue)Using “better than peer” as closure of an exposed-server factor.
EDR / vuln scanner inputData Fabric connector, then the named Risk360 factor (e.g. CrowdStrike - Zero Trust Score)Assuming ZTE telemetry already covers CrowdStrike unmanaged devices.

Runbook Side A / B / C

Side A is feed and dashboard read. Side B is the factor and the recommended action. Side C is the owning control and the re-score. Do not start at C, and do not start in Jira.

Side A — seed the surface, read the average

  1. Admin role, then Seeds Management

    Experience Center: add a Risk360 admin role and assign it via ZIdentity / Authentication Service entitlements. Then Administration › Admin Management › Administrator Management › Seeds Management. Add lab.example (max 10 domains, or CSV). First scan 24–48 h; then weekly. Source: Step-by-Step Configuration Guide for Risk360; Adding a Domain for External Attack Surface Analysis.

  2. Open Dashboard — name the band and the category

    Analytics › Risk360 › Dashboard (or Risk360 Admin Portal › Dashboard). Read the org band (Low / Medium / High / Critical). Identify which of the four categories is driving it. Do not quote a made-up integer in the ticket. Source: About the Dashboard in Risk360.

https://admin.zscaler.net/ · Analytics › Risk360 › Dashboard
Training mock · not live

Analytics / Risk360 / Dashboard

Organisation risk score

High (51–75)
Default (Zscaler-defined)
External Attack Surface
$ hover → View Details
exposed servers · Category External Attack Surface · Your Score ≠ 0 · Entities Assets · Licensed? Y
View All Factors High Impact Recommendations

Training mock. Band is documented; no tenant integer is invented. Next click: View All → Factors, or Explore on a High Impact Recommendation. Source: About the Dashboard in Risk360.

Side B — factor drawer, then Insights

  1. Open the factor — List View first

    Factors. Attack-based List View is one list you can CSV-export (export ignores UI filters). Tree View is entity-based. Columns: Factor Name, Category, Your Score, Last 30 Days, Entities, Licensed?, Recommended Actions. Click a column (not Licensed?, Include, or Entities) for the drawer. Source: About Factors.

  2. Read Details before changing policy

    Drawer: severity (critical / high / medium), recommended actions, description, help article, link to the Zscaler service responsible for the factor. Notes are yours. Related problems jump to Insights. If Licensed? is N, stop and name the missing feature — do not “tune” an unrelated ZIA rule.

  3. Insights = the remediation queue

    Insights: problem title, category, generated day, problem statement, recommendation, trend, Explore. High Impact Recommendations on the dashboard View All lands here. Source: About Insights in Risk360.

https://admin.zscaler.net/ · Risk360 › Factors › drawer
Training mock · not live

Factors / List View / exposed servers

Factor drawer · Details

exposed servers
External Attack Surface
not 0 (0 = healthy)
High
Assets
Y
Follow Insights recommendation; jump to the responsible Zscaler service. Do not exclude the entity to drop the average.
Notes Explore problem

Training mock. “exposed servers” is a dashboard example of an underlying factor, not a made-up product SKU. Your Score is shown as not-0 on purpose — this page does not invent a tenant integer. Source: About Factors; About the Dashboard.

Investigation notes (ticket body — copy the fields, not a fake score)
Tenant: lab.example (seed)
Org band: High (51-75)     # documented range, not a made-up integer
Category moved: External Attack Surface
Factor: exposed servers
Your Score: not 0 (0 = healthy)
Severity: High
Entities: Assets
Licensed?: Y
Last 30 Days: rising
Recommended action: (paste from drawer / Insights)
Owning control: (ZIA / ZPA / seed / Data Fabric connector)
Proof after change: Last 30 Days + Your Score toward 0
Do not: exclude entity without Entity Override Note; do not quote peer as closure

Side C — change the owning control, then re-score

  1. Fix where the factor is generated

    Use the drawer’s jump to the responsible Zscaler service. External Attack Surface often means take the host off the internet (or correct the seed). Compromise / Data Loss often means ZIA threat or DLP policy. Lateral Propagation often means ZPA / segmentation. Third-party named factors need the Data Fabric connector actually ingesting (CrowdStrike CrowdScore, Qualys, Tenable, Rapid7 InsightVM, Wiz, Microsoft Defender for Endpoint — as documented). Source: Integrating 3rd-Party Connectors for Risk Factors; What is Risk360.

  2. Include / exclude is an override, not a patch

    On Investigate, Include toggle + Entity Override Note (reason required). Multi-entity edits share one note. Username and reason go to audit logs. Use this for false attribution, not to paint the board pack green. Source: Investigating Sections of a Problem.

  3. Prove on the factor, not on Jira

    Re-open the same factor. Last 30 Days should bend. Your Score should move toward 0. Org band may lag because it is an average of four categories. Optional: alert rule on org / factor-group / factor score change, or on potential financial loss — email or webhook (Analytics › Risk360 › Alerts › Webhooks). Source: About Alerts; About Factors.

Green proof

Same factor row: Last 30 Days no longer rising, Your Score toward 0, Licensed? still Y, entity still included. Org band may still be High if another category did not move — that is the average working as designed, not a failed fix.

One investigation after go-live

Monday: Dashboard High (51–75). External Attack Surface is the category that moved. Top 10 shows exposed servers, entity Assets, Licensed? Y, Your Score not 0. Drawer recommended action plus Insights Explore name the internet-facing asset on seed lab.example. Owner takes the host off the public edge (or you wait out the 24–48 h if the seed was only just added). You do not exclude the entity. You do not reset a ZIA User Risk Score to Low.

Wednesday: same factor, Last 30 Days bending down, Your Score nearer 0. Compromise and Data Loss unchanged, so the org average may still sit in High. That is expected. File residual risk against the other two categories, not against this factor.

Proof · factor trend toward healthy, not a closed ticket
Engineer verifying a downward risk trend and remediated checks on a monitor
Ops feel. The actual evidence is the factor’s Last 30 Days graph and Your Score toward 0. Artwork checkmarks are not Risk360.
Alert on the factor, not only the average

Alert rules can fire on change in risk score at organisation, factor-group, and factor levels, and on change in potential financial loss. If you only alert on the org tile, a loud External factor can be cancelled in the average by a quiet Data Loss category until it is too late for the owner.

Traps + proof

SymptomLikely causeProof
High org tile, owners refuse the ticketNobody opened the factor / entity / recommended actionDashboard Top 10 + Factors drawer fields in the ticket body
EAS category empty or staleNo seed domain, or still inside 24–48 h first scanSeeds Management list; scan frequency weekly after add
Recommended action does nothingLicensed? = N, or jump link ignored and a random ZIA rule was editedLicensed? column; drawer link to the responsible service
Org number dropped overnight, server still publicInclude toggle excluded the entityAudit log: username + Entity Override Note
“We beat industry”Peer strategy used as closurePeer Score Settings (default vs custom). Factor Last 30 Days unchanged
CrowdStrike / Qualys factor silentData Fabric connector not ingestingConnector config; named factors in the 3rd-party table
Jira Resolved, board still HighAverage of four categories; other category still loud — or factor never movedSame factor Your Score still not 0; check the other three categories
User Risk Score reset to LowWrong object. That is ZIA user behaviour, not the org factorFactors page still lists the org factor
Do not globally block to “move the average”

The recommended action is scoped to the factor and the responsible service. A tenant-wide ZIA block to paint the org tile is how you create the next outage ticket. Follow Insights, then prove on that factor’s Last 30 Days.

Pilot checklist

Knowledge check

Six judgment items. Submit once. Reasons point back at the section to re-read.

Q1

Dashboard shows High (51–75). Application owners say the number is not a work item. First move?

Correct: b. Org score is an average of four stages. The work item is the factor. Re-read Why the org number is not a ticket and Flow 1.
Q2

On a factor row, what does Your Score of 0 mean?

Correct: a. Documented: the total score for a factor depends on its severity, 0 being a healthy score. Licensed? and peer are different columns. Re-read Score, category, factor, entity.
Q3

Licensed? shows N on the factor you want to fix. What is true?

Correct: c. Licensed? is whether you subscribed to the feature required to implement the recommended action (Y/N). It is not a health bit. Re-read Flow 1 and Side B.
Q4

Which answer treats the board-pack number as separate from fixing the factor?

Correct: d. Actionable means factor fields plus Insights, not the average, not dollars, not a hidden row. Re-read Flow 2 and Side B.
Q5

What is proof that remediation on this factor actually landed?

Correct: c. Closure is the factor trend and Your Score toward healthy. Org band may lag because it averages four categories. Re-read Side C and Traps.
Q6

You want to drop an entity out of score computation. What is the documented path?

Correct: a. Include/exclude requires an explanation and is audited. Exclusion is an override, not remediation. Re-read Side C and Traps.

Sources

Related: Zero Trust Exchange factory · ZIA authentication (SAML + SCIM) · ZIA DLP · ZPA access policy · Cortex Xpanse — internet-facing asset